Seriously. Defending cyber infrastructure is hard. Incredibly hard. If you only play defense you lose. Always. 100% of the time. Nuclear facilities and critical infrastructure get hacked when they aren't even connected to the broader internet. Our software stacks are built insecure from the ground up.
And what's the threat model you want to Home Depot to protect you against? Hackers coming in directly from the internet? Hackers coming in from a contractor (like Target)? Hackers breaching their corporate datacenters? Attackers that gain access to the production line? Attackers that return goods after they've been infected? Attackers that phish for access to employees or with PDF malware as job applications? Leaving infected CDs, harddrives, and USB sticks near the company HQ of the business they buy their point of sales device from? Creating rouge access points or using femto cells to gain access to company devices? Hacking into home devices of employees? Attackers planting backdoors into the hardware at the manufacturing level? Attackers guessing weak passwords that employees configured? From these attacks applied to vendors and partners? From attackers that compromise tools used by employees hosted on C|NET and others (like sysinternals)? There's a million ways in. Point of sales devices are just one way adversaries could collect this data.
Security researchers have been crying that the internet has no clothes for decades. The internet is a wild west without vigilantes. It's been designed weak from the start. Adversarial-tolerant design costs far, far more than fault-tolerant design does.
Wall Street was hacked. The Department of Defense is routinely hacked. The _NSA_ has been hacked.
This isn't Home Depot's fault. Everyone gets hacked. Everyone.